domenica 15 giugno 2025 08:01mobile   |   3dfxzone.it   |   amdzone.it   |   atizone.it   |   forumzone.it   |   hwsetup.it   |   nvidiazone.it   |   unixzone.it 
  ATIZONE.IT
  proudly powered by 3dfxzone.it
Home    |    News    |    Headlines    |    Articoli    |    Download    |    Community    |    Condividi    |    Contatti    |    Tag    |    Ricerca    |    Sitemap
 
Pubblicità Informazioni e Release Notes del file: Google Chrome 2.0.172.43 Ultime News
Condividi su Facebook Condividi su Twitter Condividi su WhatsApp Condividi su reddit

Google Chrome 2.0.172.43 has been released to the Stable channel to fix the security issues listed below.

CVE-2009-2935 Unauthorized memory read from Javascript

A flaw in the V8 Javascript engine might allow specially-crafted Javascript on a web page to read unauthorized memory, bypassing security checks. It is possible that this could lead to disclosing unauthorized data to an attacker or allow an attacker to run arbitrary code.

More info: http://code.google.com/p/chromium/issues/detail?id=18639 (This issue will be made public once a majority of users are up to date with the fix.)

Severity: High.  An attacker might be able to run arbitrary code within the Google Chrome sandbox.

Credit: This issue was found by Mozilla Security.

Mitigations:

  • A victim would need to visit a page under an attacker’s control.
  • Any code that an attacker might be able to run inside the renderer process would be inside the sandbox. Click here for more details about sandboxing.

Security Fix: Treat weak signatures as invalid

Google Chrome no longer connects to HTTPS (SSL) sites whose certificates are signed using MD2 or MD4 hashing algorithms. These algorithms are considered weak and might allow an attacker to spoof an invalid site as a valid HTTPS site. 

More info: http://code.google.com/p/chromium/issues/detail?id=18725 (This issue will be made public once a majority of users are up to date with the fix.)

Severity: Medium.  Further advances in attacks against weak hashing algorithms may eventually permit attacks to forge certificates.

Credit:  Dan Kaminsky, Director of Penetration Testing, IOActive Inc., Meredith Patterson and Len Sassaman. See their paper at http://www.ioactive.com/pdfs/PKILayerCake.pdf

CVE-2009-2414  Stack consumption vulnerability in libxml2

CVE-2009-2416  Multiple use-after-free vulnerabilities in libxml2 

Pages using XML can cause a Google Chrome tab process to crash. A malicious XML payload may be able to trigger a use-after-free condition. Other tabs are unaffected.

More info: See the CVE entries noted in this report.

Severity: High.  An attacker might be able to run arbitrary code within the Google Chrome sandbox.

Credit: Original discovery by Rauli Kaksonen and Jukka Taimisto from the CROSS project at Codenomicon Ltd. The Google Chrome security team determined that Chrome was affected.

Mitigations:

  • A victim would need to visit a page under an attacker’s control.
  • Any code that an attacker might be able to run inside the renderer process would be inside the sandbox. Click here for more details about sandboxing.

14.06.2025  
ImgDrive 2.2.3 crea drive virtuali per utilizzare i file ISO con gli OS Windows
Wine 10.10 esegue il software nativo per Windows su Linux, Unix e MacOS
13.06.2025  
Rufus 4.8 formatta e crea drive flash USB avviabili da immagini ISO
Privacy Eraser Free 6.20 protegge la privacy degli utenti di Microsoft Windows
11.06.2025  
Open Source Multi-track Audio Editing & Recording Tools: Audacity 3.7.4
Backup & Mastering Utilities: BurnAware Free 18.7 - New Enhancements
10.06.2025  
Matrox annuncia la video card LUMA Pro A380 Octal con due GPU Intel Arc A380E
The Linux Kernel Organization rilascia il Linux Kernel 6.15.2: info e download
Free Antivirus & Antimalware Utilities: Trellix Stinger 13.0.0.372 [Portable]
09.06.2025  
Activision pubblica il teaser trailer del video game Call of Duty: Black Ops 7
L'utility Open Source ReShade 6.5.1 può migliorare la resa grafica dei videogame
ScreenToGif 2.41.3 consente di creare animazioni in formato gif e video
08.06.2025  
Radeon Software Adrenalin Edition 25.6.1 - RX 9060 XT & AI PRO R9700 Ready
GeForce RTX 5050, in arrivo la entry level della linea RTX 50: prime specifiche
07.06.2025  
Hardware Monitoring & Benchmark: AIDA64 Extreme Edition 7.99.7808 beta
CD Projekt Red ed Epic Games mostrano la demo di The Witcher 4 con Unreal Engine
Network Monitoring & Security Tools: Kerio Control Firewall 9.5.0 build 8778
Kuroutoshikou annuncia le video card Radeon RX 9060 XT Dual Fan 8GB e 16GB
Sandisk & Western Digital | Tuning & Monitoring: Sandisk Dashboard 5.0.2.3
GIGABYTE introduce la video card AORUS GeForce RTX 5090 STEALTH ICE 32G
Indice delle news 
Ultimi File
Call of Duty: Black Ops 7 | Official Teaser
AMD Radeon Software Adrenalin Edition 25.6.1
The Witcher 4 - Unreal Engine 5 Tech Demo 4K Screenshots
The Witcher 4 - Unreal Engine 5 Tech Demo Video
GPU Shark 2.8.2 [Portable]
GPU-Z 2.66.0
GPU Caps Viewer 1.64.2.0 [Portable]
AMD Radeon Software Adrenalin Edition 25.5.1
Grand Theft Auto VI Screenshots
Grand Theft Auto VI Trailer 2
Indice dei file 
3dfxzone.it   ][   amdzone.it   ][   atizone.it   ][   forumzone.it   ][   hwsetup.it   ][   nvidiazone.it   ][   unixzone.it   ][   links   ][   feed rss   ][   chi siamo   ][   sitemap
ATIZone.it è servito da una applicazione proprietaria di cui è vietata la riproduzione parziale o totale (layout e/o logica). I marchi e le sigle in esso citate sono proprietà degli aventi diritto. Note Legali. Privacy.